Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 96 of 166|Showing 4751-4800 of 8293
cedars-sinai.org favicon

Cedars-Sinai

cedars-sinai.org

65
HealthcareUnited StateslargeMEDIUM

Cedars-Sinai is a leading nonprofit academic healthcare organization based in Los Angeles, California, providing world-class specialty care, pioneering research, and education. The website reflects a mature digital presence with comprehensive information on specialty programs, virtual care, clinical trials, and patient resources. The organization holds a strong market position in Southern California healthcare, supported by patient testimonials and affiliations such as the LA28 Olympic Games medical provider role. Technically, the site leverages modern frameworks including React and Adobe Experience Manager, with integrations for marketing and analytics tools like Marketo and Adobe Launch. Security posture is robust with HTTPS, security headers, and no visible vulnerabilities, though public security policies and incident response contacts are not prominently disclosed. Privacy and cookie policies are present with consent mechanisms, indicating good compliance practices. WHOIS data is unavailable, likely due to privacy protection, which is justified for this type of organization. Overall, the website demonstrates high professionalism, trustworthiness, and technical maturity.

75
53
17
50
75
65
100
healthcaremedicalhospitalspecialtycarevirtualcare+3 more
ReactAdobe Experience ManagerMarketoGoogle Maps API+1

Partner Domains:

secondopinion.cedars-sinai.org
service
csconnect.cedars-sinai.org
service

+1 more partners

2025-07-27T12:56:31.161Z
L

Lulu Press, Inc.

lulu.com

65
E-commerceUnited StateslargeMEDIUM

Lulu Press, Inc. operates a leading online self-publishing and print-on-demand platform that enables authors and publishers to create, print, and sell books globally. The company offers a comprehensive suite of services including custom book printing, ebook creation, ecommerce integrations with platforms like Shopify, Wix, and WooCommerce, and global retail distribution reaching over 40,000 retailers. Their business model focuses on eliminating inventory risk through print-on-demand technology, catering primarily to self-publishers, small publishers, and businesses. Technically, the website is built using modern web technologies including React and Next.js, ensuring fast performance, mobile responsiveness, and good SEO practices. The site is well-structured with comprehensive metadata, Open Graph tags, and JSON-LD structured data enhancing discoverability and social sharing. Accessibility and user experience are strong, with clear navigation and professional design. From a security perspective, the site enforces HTTPS with strong SSL configuration and includes standard security headers. No critical vulnerabilities or exposed sensitive data were detected. However, the absence of a visible cookie consent mechanism and explicit security or incident response policies represent minor compliance gaps. The WHOIS data confirms the legitimacy of the domain with consistent registration details matching the business identity. Overall, Lulu.com presents a trustworthy, professional, and technically sound platform with a strong market position in the self-publishing industry. Strategic improvements in privacy compliance and security transparency would further enhance trust and regulatory adherence.

30
53
2
85
75
85
100
self-publishingprint-on-demandebooksbookprintingecommerce+2 more
ReactNext.jsJavaScriptGoogle Fonts

Partner Domains:

lulujr.com
subsidiary
shopify.com
partner

+2 more partners

2025-07-27T12:54:12.148Z
syftdata.com favicon

Syft Data, Inc.

syftdata.com

10
TechnologyN/asmallCRITICAL

Syft Data, Inc. operates a sophisticated AI-powered SaaS platform designed to identify high-intent person-level leads from inbound website traffic and LinkedIn engagements. Their solution enables marketing and growth teams to uncover anonymous visitors, enrich signups, and orchestrate multi-channel outreach campaigns in real time, thereby maximizing revenue opportunities. Positioned as a lean and fast-moving technology provider, Syft emphasizes automation and data-driven decision-making to accelerate pipeline growth. Technically, the website is built on a modern Next.js framework with React, leveraging third-party services such as Cookiebot for consent management and Google Tag Manager for analytics. The site is well-optimized for mobile devices, features good SEO practices, and integrates multiple marketing and tracking tools. Performance is moderate with a clean, professional design and clear navigation. From a security perspective, the site enforces HTTPS and uses consent management to comply with GDPR. However, it lacks explicit security headers and a public security policy or incident response page. No vulnerabilities or exposed sensitive data were detected in the HTML content. The absence of WHOIS data for the domain is a notable gap, raising questions about domain registration transparency. Overall, Syft presents a credible and professional online presence with strong business and privacy compliance indicators. The main risk lies in the missing WHOIS information, which should be investigated further to confirm domain legitimacy and ownership. Strategic improvements in security policy transparency and header implementation would enhance trust and security posture.

-
-
-
-
-
-
-
aileadgenerationmarketingautomationb2bsaas+3 more
Next.jsReactCookiebotGoogle Tag Manager+1

Partner Domains:

getsyft.app
partner
2025-07-27T12:51:24.313Z
cure51.com favicon

Cure51

cure51.com

53
HealthcareFrancesmallMEDIUM

Cure51 is a specialized TechBio company focused on cancer research and drug discovery by leveraging a unique database of cancer survivors known as Outliers. The company collaborates with leading international oncology centers and renowned scientific leaders to develop precision medicine tools and novel therapeutic targets. Their market position is that of an innovative and credible player in the healthcare and biotechnology sectors, with a strong emphasis on scientific rigor and partnerships. Technically, the website is built on a modern React and Next.js stack, hosted and registered via Cloudflare, and uses Matomo for privacy-conscious analytics. The site is well-optimized for performance, mobile responsiveness, and SEO, reflecting a mature digital infrastructure. From a security perspective, the site enforces HTTPS and has domain transfer protections but lacks DNSSEC and published security policies or incident response contacts. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is well addressed with clear privacy and cookie policies and GDPR indicators. Overall, Cure51 presents a trustworthy and professional online presence with minor security and compliance improvements recommended to enhance trust and resilience.

15
68
17
70
52
75
40
canceroncologyprecisionmedicinebiotechresearch+3 more
ReactNext.jsMatomo AnalyticsCloudflare DNS and registrar

Partner Domains:

gustaveroussy.fr
partner
vhio.net
partner

+3 more partners

2025-07-27T11:47:48.771Z
havenenergy.com favicon

Haven

havenenergy.com

66
EnergyUnited StatesmediumMEDIUM

Haven Energy is a California-based company specializing in residential solar and battery backup systems, leveraging state rebate programs such as the SGIP Equity rebate to offer no-cost or reduced-cost installations to qualifying homeowners. Their market position is focused on providing reliable, clean energy solutions that reduce electric bills and protect against power outages. The company demonstrates a strong brand presence with clear trust indicators including BBB accreditation and industry association memberships. Technically, the website is built on modern frameworks such as Next.js and React, hosted on AWS infrastructure, and integrates advanced analytics and marketing tools like Google Tag Manager, PostHog, and HubSpot, reflecting a mature digital infrastructure with good performance and mobile optimization. Security posture is solid with HTTPS enforced and no visible vulnerabilities, though the absence of security headers and published security policies suggests room for improvement. Privacy compliance is basic, lacking explicit cookie consent mechanisms and GDPR compliance indicators. Overall, the website is professional, trustworthy, and well-structured, supporting the company’s credibility in the energy sector.

30
53
25
75
72
85
100
solarbatterybackupenergyrenewableenergycalifornia+2 more
ReactNext.jsClerk.jsWebpack+4

Partner Domains:

haven-energy.rippling-ats.com
partner
havenenergy.referralrock.com
partner
2025-07-27T11:47:28.267Z
gultsch.social favicon

Daniel Gultsch

gultsch.social

59
TechnologyGermanysmallMEDIUM

The website gultsch.social is an independent Mastodon instance operated by Daniel Gultsch, a recognized figure in the open source and XMPP communities. The platform emphasizes ethical design, decentralization, and user data ownership, catering to users interested in federated social networking. The business model is community-driven without advertising, focusing on technology enthusiasts and privacy-conscious users. The domain registration and website content are consistent, reflecting a small but credible operation. Technically, the site runs Mastodon 4.4.0 with modern web technologies including Ruby on Rails and React. The infrastructure appears well-maintained with HTTPS enforced and a moderate performance profile. Mobile optimization and accessibility are adequate, though some SEO and security header enhancements could improve the overall technical posture. Security-wise, the site benefits from HTTPS and domain transfer protections but lacks DNSSEC and explicit security policies. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is partial, with a basic privacy policy but no cookie consent mechanism. No incident response or vulnerability disclosure information is published. Overall, the site presents a low-risk profile with strong business credibility and technical maturity for its scale. Strategic improvements in security headers, privacy compliance, and incident response transparency would enhance trust and resilience.

75
58
17
60
72
70
40
mastodonsocialnetworkdecentralizedopensourcexmpp+2 more
Mastodon 4.4.0Ruby on RailsReactJavaScript ES Modules+1
2025-07-27T11:41:42.582Z
flathub.org favicon

Flathub

flathub.org

75
TechnologyUnited StatesmediumMEDIUM

Flathub is a prominent app store platform dedicated to Linux users, providing a centralized repository for discovering, installing, and updating Linux applications packaged as Flatpaks. Established in 2016, it serves a global audience of Linux enthusiasts and developers, offering hundreds of apps including popular titles like Firefox, Telegram, and GIMP. The platform emphasizes ease of use and broad compatibility across Linux distributions, positioning itself as the primary app distribution channel in the Linux ecosystem. Technically, Flathub employs modern web technologies including React and Next.js, delivering a fast, responsive, and accessible user experience optimized for both desktop and mobile devices. The site is hosted with reputable providers and uses HTTPS with strong SSL configurations, ensuring secure communications. Analytics are handled via Matomo, reflecting a moderate level of user tracking with some privacy considerations. From a security perspective, Flathub demonstrates good practices such as HTTPS enforcement and domain transfer protection. However, it lacks explicit published privacy, cookie, security, and incident response policies on the main site, which are important for compliance and user trust. The domain registration is consistent and stable, reinforcing the legitimacy of the platform. Overall, Flathub presents a professional, trustworthy, and technically mature platform with room for improvement in privacy compliance and security transparency. Strategic enhancements in these areas would further strengthen user confidence and regulatory adherence.

95
58
25
70
100
70
100
linuxappstoreflatpakopensourcesoftwaredistribution
ReactNext.jsJavaScriptMatomo Analytics
2025-07-27T11:41:02.512Z
lihe.org.uk favicon

London Institute for Healthcare Engineering

lihe.org.uk

57
HealthcareUnited KingdommediumMEDIUM

The London Institute for Healthcare Engineering (LIHE) is a pioneering MedTech venture builder based in the UK, affiliated with King's College London. It focuses on accelerating medical technology innovations from research to market, supporting entrepreneurs, SMEs, and industry partners. The institute offers executive support, collaborative physical space, and educational programs such as an MSc in MedTech Innovation and Entrepreneurship. LIHE is well-positioned in the MedTech ecosystem with strong partnerships and funding from reputable organizations. Technically, the website is built on modern frameworks including Next.js and React, leveraging Prismic CMS for content management. It demonstrates excellent performance, mobile optimization, and SEO practices. Security posture is strong with HTTPS, security headers, and no visible vulnerabilities, though it lacks a visible cookie consent mechanism and dedicated security policy pages. Overall, LIHE's digital presence reflects a professional, trustworthy, and credible organization with a clear mission and strong ecosystem connections. The website is safe, accessible, and well-structured, supporting its business objectives effectively.

40
53
2
60
52
60
100
medtechhealthcareinnovationventurebuildereducation+1 more
ReactNext.jsPrismic CMSGoogle Tag Manager

Partner Domains:

kcl.ac.uk
parent
siemens-healthineers.com
partner

+1 more partners

2025-07-27T10:37:18.584Z
incard.co favicon

Incard Ltd

incard.co

49
FinanceUnited KingdomsmallHIGH

Incard Ltd operates a specialized financial platform tailored for ecommerce businesses, offering multi-currency business accounts, corporate Visa Platinum cards with cashback and rewards, expense management, accounting automation, and financial analytics. Positioned as a fintech innovator, Incard targets ecommerce entrepreneurs seeking streamlined financial operations and enhanced visibility into their cash flow and advertising spend. The company leverages partnerships with Currency Cloud, Visa, and TrueLayer to provide regulated payment and account information services, reinforcing its credibility in the financial sector. Technically, the website is built on a modern React and Next.js stack, hosted on Vercel, and integrates multiple analytics and marketing tools such as Google Tag Manager, Facebook Pixel, Hotjar, and Intercom. The site demonstrates excellent mobile optimization, accessibility, and SEO practices, contributing to a professional user experience. Security posture is strong with HTTPS enforcement, comprehensive security headers, and no visible vulnerabilities or exposed sensitive data. Privacy compliance is supported by detailed privacy and cookie policies, though an explicit cookie consent mechanism is not detected. WHOIS data is privacy protected, which is justified for a fintech company, though it limits direct registrant verification. Overall, Incard presents a trustworthy and professional digital presence with a solid foundation for ecommerce financial services.

-
-
-
52
72
80
100
fintechecommercebusinessaccountscorporatecardsfinancialanalytics+2 more
ReactNext.jsVercel hostingGoogle Tag Manager+4

Partner Domains:

currencycloud.com
partner
visa.com
partner

+1 more partners

2025-07-27T09:20:29.572Z
lgbt.io favicon

Privacy service provided by Withheld for Privacy ehf

lgbt.io

60
TechnologyIcelandsmallMEDIUM

LGBT.io operates as a niche Mastodon social media instance dedicated to serving the LGBT+ community and allies. It provides decentralized social networking services leveraging the open-source Mastodon platform, fostering a moderated and inclusive environment. The platform is community-supported financially via Patreon, LiberaPay, and PayPal, indicating a patronage business model. The website content is well-structured, with clear code of conduct and active moderation staff, reinforcing its community focus and trustworthiness. Technically, the site uses a modern tech stack based on Mastodon with React and JavaScript, hosted likely via Spaceship, Inc. and Bunny.net CDN. The site is mobile-optimized and performs moderately well, though accessibility features are basic. SEO practices are adequately implemented with proper meta tags and Open Graph data. However, some security best practices such as DNSSEC and security headers are missing, and no cookie consent mechanism is present. From a security perspective, the site enforces HTTPS and has domain transfer protections. Content moderation policies are comprehensive, disallowing illegal and explicit content, which enhances safety. However, the absence of published security policies, incident response contacts, and cookie consent reduces compliance maturity. The WHOIS data shows privacy protection, which is justified given the community nature of the service, and the domain age supports legitimacy. Overall, LGBT.io presents a trustworthy, community-oriented social media platform with good technical foundations but could improve in privacy compliance and security transparency. Strategic recommendations include enabling DNSSEC, adding security headers, publishing security and incident response policies, and implementing cookie consent to enhance compliance and user trust.

75
53
17
65
72
80
40
mastodonsocialmedialgbtdecentralizedfediverse
MastodonReactJavaScriptCSS+1
2025-07-27T07:59:19.748Z
bday.quest favicon

bday.quest (beta)

bday.quest

57
TechnologyN/asmallMEDIUM

bday.quest is a small, beta-stage online platform focused on creating and sharing virtual birthday cards. The service allows users to create a card, collect personalized birthday wishes via a shared link, and celebrate together by revealing the card on the special day. The website targets a general audience interested in digital greeting solutions and leverages modern web technologies such as Next.js and Clerk.js for authentication and frontend rendering. The platform is positioned as a niche player in the virtual greeting card market with a simple and user-friendly interface. From a technical perspective, the website employs a modern React-based framework (Next.js) and integrates Clerk.js for user authentication. The site shows moderate performance and good mobile optimization but lacks advanced SEO and accessibility features. There is no evidence of a CMS or specific hosting provider from the data provided. The site does not appear to use analytics or advertising technologies, indicating a minimal tracking approach. Security posture is weak due to the absence of visible security headers, lack of privacy and cookie policies, and no contact or incident response information. The domain WHOIS data is privacy protected, which is common for small startups but reduces transparency. No critical vulnerabilities or exposed sensitive data were detected in the HTML content. Overall, the site is safe for general audiences but requires improvements in security and compliance to enhance trustworthiness. The overall risk is moderate with recommendations to implement security best practices, add privacy and cookie policies, and provide clear contact and incident response information to improve compliance and user trust.

35
50
2
60
72
75
100
virtualbirthdaycardsgreetingcardsonlinecardsbirthdaywishesbeta
ReactNext.jsClerk.js
2025-07-27T07:52:56.548Z
cnrad.dev favicon

Conrad Crawford

cnrad.dev

59
TechnologyN/asmallMEDIUM

The website cnrad.dev serves as a personal portfolio and professional presence for Conrad Crawford, a self-taught frontend-focused software engineer. The site highlights his experience with various companies, contract work, and open source projects, positioning him as a skilled individual contributor in the technology sector. The business model centers on personal branding and showcasing technical expertise to potential employers or collaborators. Technically, the site is built using modern web technologies including Next.js and TypeScript, delivering fast performance and excellent mobile optimization. The design is professional and user-friendly, with clear navigation and relevant content. Security posture is solid with HTTPS enforced and no visible vulnerabilities, though the absence of security headers and formal security policies suggests room for improvement. Privacy compliance is minimal, lacking privacy and cookie policies, which is typical for personal sites but may limit trust for some users. Overall, the domain registration data aligns well with the website content, supporting legitimacy and trustworthiness. Strategic recommendations include adding privacy and security policies, implementing security headers, and establishing a vulnerability disclosure process to enhance security and compliance.

30
35
2
70
75
75
100
softwareengineerportfoliofrontendtypescriptnextjs+2 more
TypeScriptReactNext.jsCSS

Partner Domains:

cside.dev
partner
incard.co
partner

+1 more partners

2025-07-27T06:48:07.818Z
m6.wtf favicon

m6.wtf

m6.wtf

61
OtherCanadasmallMEDIUM

The website m6.wtf currently serves as a placeholder with minimal content, displaying only a 'SOON™️' message and a brief description stating 'srry, nothing here yet'. There is no substantive business information, contact details, or policies available, indicating that the site is either under development or inactive. The domain is registered through Porkbun LLC with a Canadian registrant and uses Cloudflare DNS services, suggesting a basic level of infrastructure readiness. The technical stack includes Next.js and React frameworks, which are modern and capable of supporting a robust web presence once fully developed. From a security perspective, the site lacks critical security headers and DNSSEC is not enabled, which are areas for improvement. No forms or data collection mechanisms are present, reducing immediate privacy risks but also indicating a lack of user engagement features. The absence of privacy, cookie, or terms of service policies means the site is currently non-compliant with GDPR and other privacy regulations. No contact or incident response information is provided, limiting transparency and trust. Overall, the site scores low on content quality, security posture, privacy compliance, and business credibility due to its placeholder status and lack of substantive information. There are no indications of malicious content or adult material, and the site is accessible without WAF or security challenges. Strategic recommendations include enabling DNSSEC, adding standard security headers, publishing privacy and cookie policies, and providing clear contact information to improve trust and compliance.

75
50
2
65
75
85
100
placeholdercomingsoonminimalcontentnextjscloudflare
Next.jsReactCloudflare DNS
2025-07-27T06:46:52.310Z
svgrepo.com favicon

SVG Repo LLC

svgrepo.com

63
TechnologyN/asmallMEDIUM

SVG Repo LLC operates a comprehensive online platform offering over 500,000 free, open-licensed SVG vectors and icons. The website targets designers, developers, and businesses seeking high-quality vector graphics for commercial use. It emphasizes community contributions and provides tools for searching, editing, and remixing SVG assets without requiring design software. The platform holds a strong market position as a large, free SVG repository with a user-friendly interface and modern web technologies. Technically, the website is built using React and Next.js frameworks, ensuring fast performance, mobile optimization, and good SEO practices. It integrates Google Analytics and Tag Manager for user tracking and marketing insights. The site employs HTTPS with excellent SSL configuration, though security headers are not explicitly detected in the provided data. No vulnerabilities or exposed sensitive data were found in the analysis. From a security perspective, the site maintains a good posture with encrypted connections and no visible security flaws. However, it lacks explicit cookie consent mechanisms and published security policies or incident response contacts. The absence of WHOIS domain registration data is a concern for domain legitimacy verification, though the website content and branding appear professional and trustworthy. Overall, SVG Repo presents a low-risk profile with strong content quality and technical implementation. Strategic improvements in security headers, privacy compliance, and domain registration transparency would enhance trust and compliance.

50
53
17
70
57
75
100
svgvectorsiconsfreeopen-license+2 more
ReactNext.jsGoogle AnalyticsTinySVG compressor
2025-07-27T06:44:05.611Z
webtoo.ls favicon

webtoo.ls

webtoo.ls

68
TechnologyN/asmallMEDIUM

webtoo.ls operates as a small, community-focused Mastodon server dedicated to open source tools within the web ecosystem. It serves maintainers, collaborators, and community members interested in federated social networking. The platform leverages Mastodon 4.3.4, a modern open source social network framework, and is hosted with performance and security considerations including HTTPS and script integrity checks. The site is well-structured, mobile-optimized, and provides a good user experience with clear navigation and branding consistency. However, it lacks visible contact information and cookie consent mechanisms, which impacts privacy compliance. From a security perspective, the site benefits from HTTPS and some security best practices but could improve by adding explicit security headers and publishing security policies or incident response contacts. The absence of WHOIS data suggests privacy protection or a new domain, which is common for small community servers but limits trust verification. No adult or explicit content is present, making the site safe for general audiences. Overall, webtoo.ls demonstrates a solid technical foundation and community-oriented business model but should enhance privacy compliance and transparency to improve trust and security posture. Strategic improvements in contact availability and security documentation would benefit the platform's credibility and user confidence.

75
53
17
75
75
75
100
mastodonopensourcesocialnetworkfediversecommunity
Mastodon 4.3.4JavaScriptReactSVG+1
2025-07-27T06:43:55.592Z
royalhackaway.com favicon

Royal Hackaway

royalhackaway.com

58
EducationUnited KingdomsmallMEDIUM

Royal Hackaway is an annual hackathon event organized by Royal Holloway's Computing Society, targeting university students aged 18 and above from the UK and worldwide. The event spans 24 hours and includes workshops, talks, mini-events, and a project fair, supported by multiple sponsors including academic departments and tech companies. The website is professionally designed with clear navigation, mobile optimization, and rich content relevant to the event. Technically, the site is built using modern web technologies such as Next.js and React, with embedded Google Maps and Font Awesome icons enhancing user experience. Performance and accessibility are strong, with no detected broken elements or errors. However, explicit privacy and cookie policies are absent, and no security.txt or vulnerability disclosure mechanisms are present. Security posture is moderate; HTTPS is used, but security headers are not detected, and no incident response contacts are provided. The lack of WHOIS data for the domain raises some concerns about domain legitimacy, though the website content and sponsorships suggest a legitimate educational event. Overall, the site is safe, trustworthy, and well-positioned for its target audience. Recommendations include publishing comprehensive privacy and cookie policies, implementing security headers, adding vulnerability disclosure information, and verifying domain registration details to enhance trust and compliance.

30
35
2
70
75
70
100
hackathoneducationuniversitytechnologyevent+4 more
Next.jsReactFont Awesome 6Google Maps Embed
2025-07-27T04:32:51.565Z